Back to blog

Trust & Verification

No DPRK Allowed -
How We Vet Our Auditors

Identity-verified, sanctions-screened and contractually bound.

Pashov Audit Group2 min read

Web3 runs on pseudonyms, which works fine for a Discord handle and a lot less well for the person reading your unreleased contracts weeks before anyone else sees them. When you hire an audit firm you hand a small group of people deep access to the most sensitive code you own, and you should know exactly who they are. We do. Nobody joins us without clearing the same set of checks first.

01

Researcher invited

candidate intake

02

Identity verification

Gov ID + liveness

03

Sanctions & watchlist check

OFAC / EU / UN

04

Payout wallet screening

illicit-activity DBs

05

Signed agreement + data consent

before day one

All checks pass?

06

Approved & onboarded

cleared to start

07

Continuous re-screening

loops back into screening, ongoing

If any check fails

END

Rejected / manual review

1. Identity verification

Every researcher verifies a government-issued ID and passes a liveness and biometric check, so we know the document belongs to the person holding it.

2. Sanctions and watchlist screening

Every verified identity is screened against global sanctions and watchlists (OFAC, EU, UN and their equivalents) and against high-risk and embargoed jurisdictions. If someone is sanctioned, or working out of a region we are barred from dealing with, that is where it ends for them.

DPRK-linked operators have spent years getting hired into crypto teams as developers and freelancers. The only place to catch that is at hiring, so that is where we do it.

3. Payout screening

Payout addresses are screened against illicit-activity databases before any funds move. Knowing who someone is says nothing about where their payout address has been, so that gets its own check.

4. Signed and consented

Every researcher signs a contractor agreement and a data-protection consent before starting. Confidentiality and the limits on what they can access are written into it, with their signature underneath.

5. Ongoing, not a signup checkbox

A clean check last year tells you nothing about today. Screening runs again automatically, for as long as someone works with us.

Accountability

Every identity is verified and kept on file, so any piece of work ties back to a specific person who signed for it. If something ever went wrong we would know exactly who to go to, and they know that going in.


Anyone who reads your code has a name on file and a signature behind them. Worth asking whoever else you let near your protocol whether they can say the same.

Questions about how we vet the team on your engagement? Start at pashov.com/request-audit, or reach out directly via Telegram.